CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Description
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-26 · CAPEC-29
CVEs mapped to this weakness (2,597)
page 11 of 130| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21535 | Hig | 0.53 | 8.1 | 0.01 | Jan 10, 2023 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | ||
| CVE-2022-44676 | Hig | 0.53 | 8.1 | 0.01 | Dec 13, 2022 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | ||
| CVE-2022-41088 | Hig | 0.53 | 8.1 | 0.01 | Nov 9, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-41044 | Hig | 0.53 | 8.1 | 0.01 | Nov 9, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-41039 | Hig | 0.53 | 8.1 | 0.01 | Nov 9, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-38047 | Hig | 0.53 | 8.1 | 0.01 | Oct 11, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-38000 | Hig | 0.53 | 8.1 | 0.01 | Oct 11, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-33634 | Hig | 0.53 | 8.1 | 0.01 | Oct 11, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-30198 | Hig | 0.53 | 8.1 | 0.01 | Oct 11, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-24504 | Hig | 0.53 | 8.1 | 0.01 | Oct 11, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-22035 | Hig | 0.53 | 8.1 | 0.01 | Oct 11, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-34702 | Hig | 0.53 | 8.1 | 0.01 | Aug 9, 2022 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | ||
| CVE-2022-37035 | Hig | 0.53 | 8.1 | 0.02 | Aug 2, 2022 | An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP… | ||
| CVE-2021-4207 | Hig | 0.53 | 8.2 | 0.00 | Apr 29, 2022 | A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious… | ||
| CVE-2021-37134 | Hig | 0.53 | 8.1 | 0.00 | Jan 3, 2022 | Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components. | ||
| CVE-2021-45710 | Hig | 0.53 | 8.1 | 0.01 | Dec 27, 2021 | An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption. | ||
| CVE-2017-13905 | Hig | 0.53 | 8.1 | 0.01 | Dec 23, 2021 | A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges. | ||
| CVE-2021-37074 | Hig | 0.53 | 8.1 | 0.01 | Dec 8, 2021 | There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation. | ||
| CVE-2021-0870 | Hig | 0.53 | 8.1 | 0.07 | Oct 22, 2021 | In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9… | ||
| CVE-2021-29986 | Hig | 0.53 | 8.1 | 0.01 | Aug 17, 2021 | A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91,… |
- risk 0.53cvss 8.1epss 0.01
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.02
An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP…
- risk 0.53cvss 8.2epss 0.00
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious…
- risk 0.53cvss 8.1epss 0.00
Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.
- risk 0.53cvss 8.1epss 0.01
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.
- risk 0.53cvss 8.1epss 0.01
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.
- risk 0.53cvss 8.1epss 0.07
In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9…
- risk 0.53cvss 8.1epss 0.01
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91,…